Off-by-one error in the iov_iter_advance function in mm/filemap.c in the Linux kernel before 2.6.27-rc2 allows local users to cause a denial of service (system crash) via a certain sequence of file I/O operations with readv and writev, as demonstrated by testcases/kernel/fs/ftest/ftest03 from the Linux Test Project.
A product calculates or uses an incorrect maximum or minimum value that is 1 more, or 1 less, than the correct value.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Linux_kernel | Linux | * | 2.6.27 (excluding) |
Linux_kernel | Linux | 2.6.27 (including) | 2.6.27 (including) |
Linux_kernel | Linux | 2.6.27-rc1 (including) | 2.6.27-rc1 (including) |
MRG for RHEL-5 | RedHat | kernel-rt-0:2.6.24.7-81.el5rt | * |
Linux | Ubuntu | hardy | * |
Linux | Ubuntu | upstream | * |
Linux-source-2.6.15 | Ubuntu | upstream | * |
Linux-source-2.6.20 | Ubuntu | upstream | * |
Linux-source-2.6.22 | Ubuntu | upstream | * |